Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54430 | OpenMetadata SQL Injection |
Github GHSA |
GHSA-x8pm-wrg2-mqmx | OpenMetadata SQL Injection |
Thu, 24 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open-metadata
Open-metadata openmetadata |
|
| CPEs | cpe:2.3:a:open-metadata:openmetadata:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Open-metadata
Open-metadata openmetadata |
Thu, 17 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
ssvc
|
Thu, 17 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query. | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-17T19:15:12.171Z
Reserved: 2024-12-06T00:00:00.000Z
Link: CVE-2024-55238
Updated: 2025-04-17T19:15:07.072Z
Status : Analyzed
Published: 2025-04-17T16:15:27.780
Modified: 2025-04-24T12:47:25.673
Link: CVE-2024-55238
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA